๐ What We'll Cover
- Why Shopify needs its own privacy policy
- Data flows specific to Shopify stores
- Shopify Payments data handling
- Shopify's built-in privacy features
- Third-party apps and data sharing
- Pixels, tracking, and server-side events
- International compliance (GDPR, CCPA, Shopify Markets)
- Using our privacy policy generator for Shopify
Why a Shopify-Specific Privacy Policy Matters
Shopify is not just your e-commerce platform. It is also a data processor. When a customer buys from your store, their personal data flows through at least four separate systems before the order is complete:
- Shopify โ hosting, checkout, customer database, order management
- Payment processor โ Shopify Payments (powered by Stripe), PayPal, or a third-party gateway
- Your apps โ email marketing (Klaviyo, Mailchimp), fulfillment (Oberlo, DSers), reviews (Judge.me, Yotpo), analytics (Triple Whale, Lifetimely)
- Tracking systems โ Facebook Pixel, Google Analytics 4, TikTok Pixel, Pinterest Tag, Snapchat Pixel
A generic privacy policy template will not cover this. It will say "we collect your name, email, and payment information" โ which is true but incomplete. It will not disclose that Shopify Payments processes credit card data on Stripe's infrastructure, or that Klaviyo stores your customers' purchase history on its own servers, or that Facebook receives customer behavior data the moment someone browses a product page.
Your privacy policy must be platform-specific to be legally compliant. Regulators in the EU (under GDPR) and California (under CCPA/CPRA) expect disclosures that accurately describe data flows. A vague, generic policy that omits platform-level processing details is a compliance risk. This guide walks through every Shopify-specific disclosure your privacy policy needs.
Data Flows Specific to Shopify Stores
Every Shopify store generates four distinct categories of personal data. Your privacy policy must address each one separately with three things: what data is collected, why (the legal basis or business purpose), and who processes it.
1. Account and Customer Profile Data
When a customer creates an account on your Shopify store, the following data is stored in Shopify's customer database:
- Full name
- Email address
- Shipping address (street, city, state/province, ZIP/postal code, country)
- Phone number (if provided)
- IP address at account creation
You control this data. You can view it, export it, and delete it from your Shopify admin. But Shopify is the data processor โ they store and maintain the infrastructure. Your privacy policy must disclose this relationship.
Sample disclosure: "Customer account data is stored in Shopify's cloud infrastructure. Shopify processes this data on our behalf as a data processor under their Data Processing Agreement, which is incorporated into Shopify's Terms of Service."
2. Order and Transaction Data
When a customer places an order, the following data is created and stored:
- All account data above
- Order number, date, and status
- Items purchased, quantities, prices, and SKUs
- Shipping method, tracking number, and delivery status
- Tax information (if tax-exempt, the exemption certificate)
- Notes or instructions added to the order
This data stays in Shopify's order records indefinitely unless you manually delete it. Your privacy policy should state the retention period for order data โ typically the duration required by tax law (often 3-7 years depending on jurisdiction).
3. Browsing and Behavioral Data
Every visitor to your Shopify store generates browsing data:
- IP address and approximate location (city/region level)
- Device type, browser, operating system, screen resolution
- Pages viewed, time on site, click patterns, scroll depth
- Referral source (how they found your store โ Google, social media, direct link)
- Products viewed, added to cart, or added to wishlist
This data flows into Shopify Analytics, Google Analytics 4 (if installed), and any pixel/event tools you use. Each destination is a separate data processor โ your privacy policy must name each category of processor.
4. Marketing and Communication Data
If you run email or SMS marketing, additional data is collected:
- Email address and subscription status (opted in or out)
- Phone number and SMS consent status
- Email open rates, click-through rates, and bounce status
- Purchase history used for segmentation and personalization
- Abandoned checkout data (email, cart contents, value)
This data flows through whatever email or SMS platform you use (Shopify Email, Klaviyo, Mailchimp, SMSBump, etc.). Each platform is a separate data processor that needs to be disclosed.
Shopify Payments Data Handling
Shopify Payments is the default payment processor for most Shopify stores. It is powered by Stripe. Understanding exactly what payment data you see versus what Stripe sees is critical for a correct privacy policy.
What You Never See
Full credit card numbers are never transmitted to or stored by your Shopify store. When a customer enters their card number at checkout, the data is sent directly from the browser to Stripe via a secure iframe. Your store's server never touches the full PAN (Primary Account Number).
What You Do See in Shopify Admin
| Data Field | Visible in Shopify? | Notes |
|---|---|---|
| Full card number | No | Tokenized by Stripe. Only the last 4 digits are available for reference. |
| Card brand | Yes | Visa, Mastercard, Amex, Discover, etc. |
| Last 4 digits | Yes | Shown on order details page for identification |
| Expiration date | Yes | Month and year |
| Billing name and address | Yes | Stored in Shopify order records |
| AVS result | Yes | Address verification system match status |
| CVC check | No | Only Stripe sees the result |
Sample disclosure for your policy: "Payment processing is handled by Shopify Payments, which is powered by Stripe. Your full payment card number is encrypted and transmitted directly to Stripe โ we never receive or store complete card numbers. We may retain the last four digits of your card number, the card brand, and the expiration date for order reference and fraud prevention. Stripe's privacy policy is available at stripe.com/privacy."
If you use PayPal, the same principle applies โ PayPal processes the payment, and you see only the transaction status and PayPal email address. PayPal's privacy policy should be linked.
PCI Compliance
Shopify is a Level 1 PCI DSS compliant service provider. Your store inherits this compliance because you never handle raw card data. Your privacy policy should note that the store does not store payment card data and relies on PCI-compliant third-party processors.
Shopify's Built-In Privacy Features
Shopify includes several privacy features that deserve mention in your privacy policy. Describing these features shows customers you take their privacy rights seriously and demonstrates that you have the technical ability to fulfill data subject requests.
Customer Data Export
Under GDPR Article 15 (right of access) and CCPA (right to know), customers can request a copy of their data. Shopify provides a built-in workflow:
- Go to Customers in your Shopify admin
- Click on the customer's name
- Click the "More actions" dropdown
- Select "Request customer data"
- Shopify generates a JSON file containing all the customer's data and makes it available for download
Your privacy policy should explain that customers can make this request by contacting you and that you will fulfill it within the legally required timeframe (typically 30 days under GDPR, 45 days under CCPA).
Customer Data Erasure
Shopify's "Erase Personal Data" button (available in the customer record) removes personal information from the customer profile while preserving order records for legal and tax retention requirements.
What gets erased: name, email, phone, shipping address, IP address, and any custom customer fields.
What stays: order number, date, items purchased, price, and payment status (anonymized โ the customer becomes "Deleted Customer" with a generic entry).
Your privacy policy should reference this capability: "When you request deletion of your personal data, we will anonymize your customer profile while retaining order records as required by tax and financial regulations."
Cookie Consent Banner
Shopify has a built-in cookie consent banner at Online Store > Preferences > Cookie consent banner. It covers basic compliance but has limitations:
- No granular cookie categorization (no "necessary," "analytics," "marketing" toggle โ just accept or reject all)
- Minimal customization options
- Does not block scripts before consent โ scripts still load, the banner just records consent preference
Data Processing Agreement (DPA)
Good news: Shopify's DPA is automatically included in your Terms of Service with them. You do not need to sign a separate DPA with Shopify. The DPA covers GDPR Article 28 requirements for data processors.
However, you do need separate DPAs with your third-party apps. Most major Shopify apps have standard DPAs available on their websites. If an app developer cannot provide a DPA, that app may not be GDPR-compliant for your store.
Third-Party Apps and Data Sharing
This is the most commonly overlooked section in Shopify privacy policies. Every app you install is a separate data processor with access to customer data. Your policy must address this.
Common App Categories and the Data They Process
| App Category | Examples | Data Accessed |
|---|---|---|
| Email marketing | Klaviyo, Mailchimp, Omnisend, Privy | Customer name, email, purchase history, browsing behavior, cart abandonment data |
| Order fulfillment | Oberlo, DSers, Printful, ShipStation | Customer name, shipping address, phone number, order contents |
| Product reviews | Judge.me, Yotpo, Loox, Stamped.io | Customer name, email, order number (to send review requests), review content |
| Analytics | Triple Whale, Lifetimely, Polar Analytics | Order data, customer data, marketing attribution, browsing behavior |
| Customer support | Gorgias, Zendesk, Re:amaze, Tidio | Customer name, email, order history, chat transcripts, support tickets |
| Loyalty and rewards | Smile.io, LoyaltyLion, Yotpo Loyalty | Customer name, email, purchase history, points balance, reward redemptions |
| Shipping and tracking | AfterShip, Shipstation, ParcelPanel | Customer name, email, shipping address, order number, tracking data |
| Subscriptions | Recharge, Bold Subscriptions, Seal Subscriptions | Customer name, email, shipping address, payment method token, subscription history |
You do not need to list every individual app by name. Your app catalog changes. Instead, describe the categories of apps and the types of data they process:
Sample disclosure: "We use third-party applications to operate our store, including email marketing platforms, order fulfillment services, product review tools, analytics providers, and customer support systems. These applications receive only the data necessary to perform their functions โ typically customer name, email address, order information, and browsing behavior. Each application provider acts as an independent data controller or data processor, and we recommend reviewing their individual privacy policies."
Your Responsibility Under GDPR
Under GDPR Article 28, you are required to have a written data processing agreement with each app that processes personal data on your behalf. When you install an app via the Shopify App Store, the app developer is required to provide a privacy policy and data processing terms. However, it is your responsibility to verify this and maintain documentation.
If an app does not have a publicly available DPA, do not install it โ or remove it if it is already installed. Non-compliant apps put your whole store at regulatory risk.
Pixels, Tracking, and Server-Side Events
Pixels are the most contentious area of Shopify privacy compliance. Here is what you need to know and what your privacy policy must say.
Facebook / Meta Pixel
The Meta Pixel (formerly Facebook Pixel) is the most widely used tracking tool on Shopify. When installed, it fires on:
- PageView โ every page visit. Sends URL, referrer, and browser info to Meta.
- ViewContent โ product page views. Sends product ID, price, currency, and category.
- AddToCart โ cart additions. Sends product details and cart value.
- InitiateCheckout โ checkout start. Sends cart value and product list.
- AddPaymentInfo โ payment info entered. Sends checkout progress data.
- Purchase โ completed order. Sends order value, currency, product list, and order ID.
Each event sends data to Meta's servers. Meta uses this data for ad targeting, ad measurement, and to build lookalike audiences. Under CCPA, sharing data with Meta via the pixel can constitute a "sale" of personal information (you share customer data in exchange for ad targeting services).
Sample disclosure: "We use the Meta (Facebook) Pixel to track conversions, build audiences for advertising, and measure the effectiveness of our ads. When you browse our store, your browser sends information to Meta about the pages you visit, products you view, and actions you take. This data is used by Meta in accordance with their privacy policy. You can opt out of Meta's use of your data through your Facebook Ad Preferences or the Off-Facebook Activity tool."
Google Analytics 4
GA4 tracks browsing behavior on your store. Key data points: pages viewed, session duration, device type, approximate location (from IP), and events (clicks, scrolls, purchases). Google acts as a data processor under Google's Data Processing Terms.
GA4 includes IP anonymization by default โ Google truncates the last octet of IPv4 addresses before storing or processing them. Your privacy policy should mention this.
Server-Side Tracking (Shopify Customer Events)
Shopify's "Customer Events" feature sends data from your server directly to Meta, Google, and other platforms โ bypassing the browser entirely. This means the tracking happens even if the customer has a browser-level ad blocker or tracking protection enabled.
Important: Server-side tracking is not a privacy loophole. Under GDPR, the purpose limitation principle still applies โ even if the data is sent server-to-server, you still need a legal basis (typically consent for marketing tracking). Your privacy policy must disclose server-side tracking if you use it.
Sample disclosure: "In addition to browser-based tracking, we use server-side event tracking via Shopify's Customer Events feature. This transmits certain purchase and browsing data directly from our server to advertising platforms, independent of browser settings. The same data protection obligations apply โ we only transmit data for purposes you have consented to or where we have a legitimate interest."
Other Pixels
If you use the TikTok Pixel, Pinterest Tag, Snapchat Pixel, or Twitter (X) Pixel, the same disclosure principles apply. Each pixel shares customer behavior data with the respective platform. Your privacy policy should either list each platform specifically or use a blanket disclosure:
"We use conversion tracking pixels from third-party advertising platforms, including but not limited to Meta (Facebook), Google, TikTok, Pinterest, and Snapchat. These pixels transmit data about your browsing and purchase behavior to the respective platforms for ad measurement and targeting."
International Compliance (GDPR, CCPA, Shopify Markets)
If you sell to customers outside your home country โ and most Shopify stores do โ you need to account for multiple privacy laws. Here is what each major regulation requires and how Shopify-specific features interact with them.
GDPR (EU and UK Customers)
If you have customers in the EU or UK, GDPR applies to your store regardless of where your business is based. Key requirements:
| Requirement | Shopify Implementation |
|---|---|
| Lawful basis for each processing purpose | Order processing = "contractual necessity." Marketing = "consent" or "legitimate interest." Analytics = "consent" (under ePrivacy, analytics cookies require prior consent). |
| Consent management | Shopify's built-in cookie banner is insufficient for GDPR. Use a consent platform that blocks tracking scripts until consent is given. |
| Data subject access requests (DSARs) | Use Shopify's "Request customer data" export. Respond within 30 days. |
| Right to erasure | Use Shopify's "Erase personal data" button. Retain anonymized order records for tax compliance. |
| Data portability | Export customer data from Shopify admin and provide in a machine-readable format (CSV/JSON). |
| Data Processing Agreement (DPA) | Shopify's DPA is included in your ToS. You still need DPAs with third-party apps. |
CCPA/CPRA (California Customers)
The California Consumer Privacy Act applies if your Shopify store meets any of these thresholds:
- Gross revenue over $25 million per year, OR
- Buys, sells, or shares personal information of 100,000+ California households or residents per year, OR
- Derives 50%+ of annual revenue from selling or sharing personal information
Key point for Shopify stores: Sharing customer data with Meta via the Facebook Pixel may be considered a "sale" under CCPA โ even if no money changes hands. The CCPA defines "sale" broadly to include sharing data for valuable consideration (ad targeting services count).
Your privacy policy must:
- Include a "Do Not Sell or Share My Personal Information" link (or a CCPA-specific opt-out mechanism)
- Disclose the categories of personal information collected, sold, and shared
- Provide two methods for submitting data requests (typically a web form and a toll-free phone number or email)
- Describe the customer's right to non-discrimination (not charging different prices for opting out)
Shopify Markets and Multi-Jurisdiction Stores
If you use Shopify Markets to sell across multiple countries, your privacy obligations multiply. Each market may have different data protection laws:
- Brazil: LGPD โ requires appointment of a Data Protection Officer (DPO) and specific consent requirements
- Canada: PIPEDA โ requires meaningful consent and purpose specification
- Australia: Privacy Act 1988 โ requires an Australian Privacy Principle (APP) compliant policy
- Japan: APPI โ requires notification of purpose of use and opt-out for third-party sharing
- South Korea: PIPA โ requires one of the strictest consent regimes globally
If you use Shopify Markets with automatic currency conversion, localized domains, or region-specific pricing, your privacy policy should acknowledge that different regions may have different data collection and processing practices, and link to region-specific addendums if applicable.
Sample disclosure: "We sell to customers in multiple countries through Shopify Markets. Depending on your location, additional privacy protections may apply as required by local law. If you are in the EEA, UK, Brazil, Canada, or Australia, specific disclosures in this policy apply to you."
International Data Transfers
Shopify's servers are primarily located in the United States (though they maintain data centers in multiple regions). If your customers are in the EU, their data is transferred from the EU to the US. Shopify relies on the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) as the legal transfer mechanism.
Your privacy policy should mention international data transfers and the safeguards in place. Sample: "Your personal data may be transferred to and processed in Shopify's servers in the United States. Shopify participates in the EU-US Data Privacy Framework and uses Standard Contractual Clauses to ensure adequate protection for international data transfers."
Using Our Privacy Policy Generator for Shopify
Writing a Shopify-specific privacy policy from scratch is time-consuming and error-prone. Our privacy policy generator walks you through every section and produces a complete, platform-specific policy tailored to your store.
How It Works
- Select your type: Choose "E-Commerce" from the business type options
- Choose your platform: Select "Shopify" as your e-commerce platform
- Configure your store: Answer questions about what apps you use, what tracking pixels are installed, whether you use Shopify Payments or a third-party gateway, and which markets you sell to
- Select your features: Check off data processing activities โ email marketing, order fulfillment, reviews, analytics, loyalty programs, subscription services, SMS marketing
- Choose your jurisdictions: Select which privacy laws apply โ GDPR, CCPA, LGPD, PIPEDA, or others
- Generate: The tool produces a complete privacy policy with all required disclosures, data processor listings, cookie categories, and data subject rights descriptions
What the Generated Policy Includes
- Complete list of data types collected (customer account, order, browsing, marketing)
- Named data processors (Shopify, Stripe, and your selected apps by category)
- Shopify Payments-specific payment data disclosures
- Cookie and tracking pixel disclosures with platform names (Meta, Google, TikTok, etc.)
- CCPA opt-out language with "Do Not Sell" mechanism
- GDPR data subject rights with Shopify-specific fulfillment methods
- International data transfer disclosures referencing Shopify's DPF/SCC compliance
- Retention periods for each data type
- Security practices (PCI DSS, encryption, access controls)
- Policy update and notification procedures
Generate Your Policy
Ready to create your Shopify privacy policy? Use our free generator at the link below. Your policy will be Shopify-specific, platform-aware, and ready to publish on your store's footer.
Ready to create your Shopify privacy policy?
Generate Privacy Policy โ
For more on e-commerce privacy policies, read our related guides: